Количество 367 277
Количество 367 277
GHSA-457j-x7h3-8hjh
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7.
GHSA-457j-cjp6-q7h3
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-457g-xg5v-227f
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17.
GHSA-457g-f88f-3329
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
GHSA-457f-xp3m-rv66
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.
GHSA-457f-wg3h-7vw8
The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with the privileges of an authenticated administrator user.
GHSA-457f-qv6r-jcjg
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process. (FG-VD-22-052, FG-VD-22-056)
GHSA-457f-q7w2-wmhh
A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.
GHSA-457f-pcj5-v75v
A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-457f-g7c4-56q4
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caused by using possible old value of msg mask table count while copying masks to userspace.
GHSA-457f-c77p-7wc3
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.
GHSA-457c-p98r-9wg6
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.
GHSA-4579-7jx6-x8r3
Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.
GHSA-4578-w77v-3r84
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
GHSA-4578-6gjh-f2jm
Mattermost allows an unauthorized Guest user access to Playbook
GHSA-4576-pgh2-g34j
derhansen/sf_event_mgt vulnerable to Broken Access Control in Backend Module
GHSA-4576-cf38-77f2
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
GHSA-4574-x3wr-77rh
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.
GHSA-4574-w5wx-78f9
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through <= 1.3.
GHSA-4574-qv3w-fcmg
Deserialization of Untrusted Data in codeception/codeception
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-457j-x7h3-8hjh Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-457j-cjp6-q7h3 Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-457g-xg5v-227f Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-457g-f88f-3329 Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file. | CVSS3: 5.5 | 3% Низкий | больше 4 лет назад | |
GHSA-457f-xp3m-rv66 It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-457f-wg3h-7vw8 The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with the privileges of an authenticated administrator user. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-457f-qv6r-jcjg A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process. (FG-VD-22-052, FG-VD-22-056) | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-457f-q7w2-wmhh A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. | 16% Средний | больше 4 лет назад | ||
GHSA-457f-pcj5-v75v A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 8.8 | 1% Низкий | около 1 года назад | |
GHSA-457f-g7c4-56q4 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caused by using possible old value of msg mask table count while copying masks to userspace. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-457f-c77p-7wc3 A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-457c-p98r-9wg6 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server. | CVSS3: 7.5 | 0% Низкий | 25 дней назад | |
GHSA-4579-7jx6-x8r3 Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI. | 5% Низкий | больше 4 лет назад | ||
GHSA-4578-w77v-3r84 NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges. | CVSS3: 8.1 | 0% Низкий | 13 дней назад | |
GHSA-4578-6gjh-f2jm Mattermost allows an unauthorized Guest user access to Playbook | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-4576-pgh2-g34j derhansen/sf_event_mgt vulnerable to Broken Access Control in Backend Module | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4576-cf38-77f2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file. | CVSS3: 7.5 | 12% Средний | больше 4 лет назад | |
GHSA-4574-x3wr-77rh Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-4574-w5wx-78f9 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through <= 1.3. | CVSS3: 8.1 | 1% Низкий | 6 месяцев назад | |
GHSA-4574-qv3w-fcmg Deserialization of Untrusted Data in codeception/codeception | CVSS3: 9.8 | 3% Низкий | около 5 лет назад |
Уязвимостей на страницу